0
blog.hofstede.it · 4h · discuss
I write Ansible for a living, and I still patched most of my own servers by hand every week. This is how that ended: a Git-based inventory, defensive patch playbooks for FreeBSD (freebsd-update and pkgbase), Bastille thin jails, classic thick jails via my jailexec connection plugin, a Proxmox cluster and RHEL. Ansible Automation Platform runs it for me, but nothing here requires it. Plus the mistakes, including the reboot policy I should have checked before the first real run.